Vulnerabilities > Yokogawa > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-0651 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Yokogawa products
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function or execute an arbitrary program via unspecified vectors.
network
low complexity
yokogawa CWE-119
7.5
2018-10-12 CVE-2018-17898 Resource Exhaustion vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests.
network
low complexity
yokogawa CWE-400
7.8
2016-09-19 CVE-2016-4860 Improper Authentication vulnerability in Yokogawa Stardom Fcn/Fcj
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.
network
low complexity
yokogawa CWE-287
7.5
2014-12-22 CVE-2014-5208 Improper Access Control vulnerability in Yokogawa Centum CS 3000, Centum VP and Exaopc
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a STOR operation, or obtain sensitive database-location information via a PMODE operation, a different vulnerability than CVE-2014-0784.
network
low complexity
yokogawa CWE-284
7.5
2014-07-10 CVE-2014-3888 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Yokogawa products
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
network
yokogawa CWE-119
8.3
2014-05-16 CVE-2014-0782 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Yokogawa products
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.
network
yokogawa CWE-119
8.3
2014-03-14 CVE-2014-0784 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Yokogawa Centum CS 3000
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
network
yokogawa CWE-119
8.3